SIG Lite Control LOG-03 Extractive Review Standard

How to answer 'How long are security logs retained?' on a SIG Lite

Reviewer Guidance & Pitfalls

State the retention duration (industry standard is at least 365 days / 1 year for audit logs, with 30–90 days readily searchable in SIEM). Mention that audit logs are write-once / append-only and protected against tampering.

Example Answer Passing Enterprise Audit

Compliant Response Template
Audit and security logs are centralized in write-protected cloud storage, retained for a minimum of 365 days, and indexed for active querying for 90 days (SOC 2, CC7.2).

Filling out a CAIQ or SIG Lite right now?

QuietQuestionnaire automatically drafts answers with citations from your own SOC 2 report, catches contradictions reviewers reject, and locks exports behind cryptographic human sign-off.

Zero spam. 100% confidential. No credit card required.